ZeroHour

CVE-2026-75439

niche

NULL Pointer Dereference DoS in Free5GC 4.2.2 UPF Component

CVSS 3.1
7.5 high
EPSS
<1%p16
Published
()
Modified
AI analysis

Free5GC version 4.2.2 contains a NULL pointer dereference (CWE-476) in its User Plane Function (UPF) component, the part of the open-source 5G core that carries subscriber data traffic. A remote, unauthenticated attacker can trigger the flaw by sending a specially crafted request to the UPF, most plausibly a malformed packet on its control interface, causing the process to crash and denying service to any users whose traffic transits that UPF. The impact is limited to availability — confidentiality and integrity are unaffected, consistent with the CVSS 7.5 score (network vector, low complexity, no privileges or user interaction required). Affected parties are operators, universities, and researchers running Free5GC 4.2.2, typically in lab or testbed environments rather than commercial networks. No public proof of concept is known, the flaw is not in the CISA KEV catalog, and EPSS places it at only 0.2% likelihood of exploitation in the next 30 days.

What to do: Upgrade to a Free5GC release newer than 4.2.2 once upstream publishes a fix, or apply the upstream patch to the UPF component directly. Restrict network reachability to the UPF's service and PFCP ports so only trusted SMF/gNodeB addresses can connect, and monitor the UPF process for unexpected crashes or rapid restarts as an indicator of malformed-message attempts.

Affected
Free5GC (UPF component)4.2.2
Estimated exposure
nichelikely tens to hundreds of instances (research/lab deployments; no reliable public count) — Free5GC is an open-source 5G core used almost exclusively in academic, research, and lab testbeds rather than production carrier networks, and no plugin install counts or public internet-scan data are available to confirm exposure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component

Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.